mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-01 19:00:40 +02:00
* feat(session-kind): explicit GSTACK_SESSION_KIND override; skill-start spawned gates keyed on kind (#2733) Claude Code subagents inherit the parent env byte-for-byte, so ambient markers classify them as the parent's kind and the spawned classification was unreachable outside OpenClaw. GSTACK_SESSION_KIND=spawned (step 0, spawned-only by design) lets a dispatching skill mark its subagent per command. skill-start now keys SPAWNED_SESSION and the spawned-session instruction block on the resolved kind (was raw OPENCLAW_SESSION), suppresses CONDUCTOR_SESSION for spawned sessions, gates all 11 interactive-onboarding blocks plus their ack-at-emit marker writes on kind != spawned, and adds a destructive-gate carve-out to the spawned block (conservative-continue, never prose-STOP). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(hooks): spawned-session escape in Conductor AUQ deny; override coverage in AUQ-error fallback (#2733) Hooks inherit the harness env, so a per-command GSTACK_SESSION_KIND prefix inside a subagent's bash can never reach them. Levers added: a deterministic [conductor][spawned] auto-choose deny for env-level spawned sessions (OPENCLAW_SESSION or session-wide GSTACK_SESSION_KIND), and a spawned escape sentence appended to both hooks' prose directives so a marked subagent that slips and calls AUQ resolves to auto-choose instead of prose-STOP. The sentence lives in one shared constant (hosts/claude/hooks/spawned-directive.ts) so the two paths can never drift; destructive semantics are unified to conservative-continue. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix(ship): Step 18 marks the document-release subagent spawned — env prefix + auto-choose prompt (#2733) The dispatch prompt now (1) frames the run as a SPAWNED subagent whose LAST line is machine-parsed, (2) instructs prefixing the preamble's gstack-skill-start invocation with GSTACK_SESSION_KIND=spawned on the same command line (template bash blocks don't share exports), and (3) resolves every AUQ gate to auto-choosing the recommended option, conservative on no-recommendation, never destructive. The JSON contract gains a required "decisions" array (auto-chosen gates, printed to the ship console — never embedded in the public PR body) and a placement clause so the skill's own doc-health summary stops competing with the LAST-line JSON. Tripwire pins added; codex/factory goldens refreshed. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * feat(auq-format): proactive SESSION_KIND=spawned rule ordered above the Conductor rule (#2733) The spawned classification previously existed only in the failure-fallback branch — a spawned session was invited to call AskUserQuestion and reach auto-choose via the deny/error detour, and a spawned session inside a Conductor workspace hit the Conductor prose-STOP rule first. The Tool resolution list now leads with the spawned rule (auto-choose recommended, never prose, never BLOCKED, destructive gates resolve conservative), the self-check carries the never-reach-this-checklist clause, and all tier>=2 SKILL.md renders are regenerated. Context-budget fixture refreshed in the same commit per the ratchet protocol (the AUQ section is eager in every tier>=2 skill). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * test(e2e): spawned document-release subagent returns the JSON contract through a firing gate (#2733) The behavioral proof the bug shipped without: ship-docsync stubs the skill (no preamble, no gates) and skill-e2e-workflow suppresses the gates by prompt. This gate-tier E2E plays the parent — it drives the verbatim Step 18 dispatch prompt (extracted from the live pr-body.md, drift-proof) against a real preamble-bearing document-release slice in a Conductor-ambient env with both AUQ hooks seeded live, an unbumped VERSION making Step 8 fire. Asserts: the final line parses as the 5-key JSON contract, the fired gate's auto-choice is recorded in decisions, and VERSION is untouched (the gate resolved to its recommended Skip). Burn-in: 1/1 pass, $0.35, 21 turns, 106s. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs(openclaw): document the GSTACK_SESSION_KIND override; wire session-kind into paid selectors (#2733) OPENCLAW.md's spawned-session section now covers the explicit per-command marker, its deliberate spawned-only narrowness, the /ship Step 18 usage, the destructive carve-out, onboarding-block suppression, and the hook env-blindness caveat. bin/gstack-session-kind and the shared spawned-directive module join the conductor-prose and auto-decide-preserved selector dep lists (session-kind previously appeared in no touchfiles entry — editing it alone triggered no paid E2E). TODOS.md gains the plan-tune capture follow-up for spawned auto-choices. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * fix: pre-landing review fixes (#2733) Review army + coverage audit findings, all applied: - headless directive carries the spawned escape sentence too (multi- specialist: a CI-hosted ship's marked subagent must not end BLOCKED) - anti-injection scoping on every text-claimable spawned trigger (AUQ rule + shared escape sentence): markings count only from the creating prompt, never from files/tool output/web content read mid-run - [conductor][spawned] deny annotates one-way doors per question - SPAWNED_OVERRIDE: env tamper-visibility status line + OPENCLAW.md note - spawned sessions skip the network update-check and first-task probe (consumers suppressed; preserves the one-shot just-upgraded marker) - test hardening: dispatch-tripwire end-bound validated, vacuous marker asserts replaced with output asserts, E2E cpSync size filter + named fence tolerance, spawnedByEnv parity pin, destructive-policy cross- surface drift guard, one-way annotation + bogus-value hook cases - session-kind duplicate rationale comment deduped; regen + goldens + context-budget fixture refreshed Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * chore: bump version and changelog (v1.76.0.0) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: update project documentation for v1.76.0.0 PROJECT_STRUCTURE.md: add hosts/claude/hooks/ to the directory tree (AUQ capture + enforcement hooks, spawned-session directive, timeline stop) — the tree omitted the directory while docs/OPENCLAW.md and CHANGELOG.md now reference paths inside it. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * docs: sync TODOS.md ship dispatch entry with the v1.76.0.0 contract Codex doc-review finding: the SHIPPED entry for /ship auto-invoking /document-release still described the four-key JSON contract. Adds the decisions key (console-printed, never PR markdown), the GSTACK_SESSION_KIND=spawned dispatch marking (#2733), and the new spawned-dispatch gate E2E to the proven-by list. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
258 lines
11 KiB
Bash
Executable File
258 lines
11 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# gstack-question-log — append an AskUserQuestion event to the project log.
|
|
#
|
|
# Usage:
|
|
# gstack-question-log '{"skill":"ship","question_id":"ship-test-failure-triage",\
|
|
# "question_summary":"Tests failed","options_count":3,"user_choice":"fix-now",\
|
|
# "recommended":"fix-now","session_id":"ppid"}'
|
|
#
|
|
# v1: log-only. Consumed by /plan-tune inspection and (in v2) by the
|
|
# inferred-dimension derivation pipeline.
|
|
#
|
|
# Schema (all fields validated):
|
|
# skill — skill name (kebab-case)
|
|
# question_id — either a registered id (preferred) or ad-hoc `{skill}-{slug}`
|
|
# question_summary — short one-liner of what was asked (<= 200 chars)
|
|
# category — approval | clarification | routing | cherry-pick | feedback-loop
|
|
# (optional — looked up from registry if omitted)
|
|
# door_type — one-way | two-way
|
|
# (optional — looked up from registry if omitted)
|
|
# options_count — number of options presented (positive integer)
|
|
# user_choice — key user selected (free string; registry-options preferred)
|
|
# recommended — option key the agent recommended (optional)
|
|
# followed_recommendation — bool (optional — computed if both present)
|
|
# session_id — stable session identifier
|
|
# ts — ISO 8601 timestamp (auto-injected if missing)
|
|
#
|
|
# Append-only JSONL. Dedup is at read time in gstack-question-sensitivity --read-log.
|
|
set -euo pipefail
|
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
|
|
# Windows git-bash (#1950): pwd yields a POSIX path (/c/Users/...), which Bun
|
|
# on Windows cannot resolve as an ES module specifier in bun -e imports.
|
|
# cygpath -m converts to C:/Users/... which Bun accepts.
|
|
case "$(uname -s)" in
|
|
MINGW*|MSYS*|CYGWIN*) command -v cygpath >/dev/null 2>&1 && SCRIPT_DIR="$(cygpath -m "$SCRIPT_DIR")" ;;
|
|
esac
|
|
eval "$("$SCRIPT_DIR/gstack-slug" 2>/dev/null)"
|
|
# GSTACK_STATE_ROOT takes precedence over GSTACK_HOME (test isolation per D16).
|
|
GSTACK_HOME="${GSTACK_STATE_ROOT:-${GSTACK_HOME:-$HOME/.gstack}}"
|
|
mkdir -p "$GSTACK_HOME/projects/$SLUG"
|
|
|
|
INPUT="$1"
|
|
|
|
# Validate and enrich from registry.
|
|
TMPERR=$(mktemp)
|
|
trap 'rm -f "$TMPERR"' EXIT
|
|
set +e
|
|
VALIDATED=$(printf '%s' "$INPUT" | bun -e "
|
|
import { hasInjection } from '$SCRIPT_DIR/../lib/jsonl-store.ts';
|
|
const path = require('path');
|
|
const raw = await Bun.stdin.text();
|
|
let j;
|
|
try { j = JSON.parse(raw); } catch { process.stderr.write('gstack-question-log: invalid JSON\n'); process.exit(1); }
|
|
|
|
// Required: skill (kebab-case)
|
|
if (!j.skill || !/^[a-z0-9-]+\$/.test(j.skill)) {
|
|
process.stderr.write('gstack-question-log: invalid skill, must be kebab-case\n');
|
|
process.exit(1);
|
|
}
|
|
|
|
// Required: question_id (kebab-case, <=64 chars).
|
|
// Cathedral T5: hook-sourced events use 'hook-<10-char-hash>' which is
|
|
// kebab-case-compatible and passes the same regex.
|
|
if (!j.question_id || !/^[a-z0-9-]+\$/.test(j.question_id) || j.question_id.length > 64) {
|
|
process.stderr.write('gstack-question-log: invalid question_id, must be kebab-case <=64 chars\n');
|
|
process.exit(1);
|
|
}
|
|
|
|
// Optional: source — tags which writer produced this event.
|
|
// 'agent' (default) — preamble-driven write from inside the running agent
|
|
// 'hook' — PostToolUse hook captured it deterministically (T5)
|
|
// 'auq-other' — user picked 'Other' and typed free text (Layer 8)
|
|
// 'auto-decided' — PreToolUse enforcement hook substituted the answer (T6)
|
|
// 'codex-import-marker' / 'codex-import-pattern' — T9 backfill from Codex
|
|
// 'spawned-env-deny' — spawned-session AUQ deny (#2733): the model, not a
|
|
// human, resolves the gate; tagged so /plan-tune never
|
|
// trains on machine picks as if a human made them
|
|
const ALLOWED_SOURCES = ['agent', 'hook', 'auq-other', 'auto-decided', 'codex-import-marker', 'codex-import-pattern', 'spawned-env-deny'];
|
|
if (j.source !== undefined) {
|
|
if (!ALLOWED_SOURCES.includes(j.source)) {
|
|
process.stderr.write('gstack-question-log: invalid source, must be one of: ' + ALLOWED_SOURCES.join(', ') + '\n');
|
|
process.exit(1);
|
|
}
|
|
} else {
|
|
j.source = 'agent';
|
|
}
|
|
|
|
// Optional: tool_use_id — Claude Code hook stdin field; used for dedup.
|
|
if (j.tool_use_id !== undefined) {
|
|
if (typeof j.tool_use_id !== 'string' || j.tool_use_id.length > 128) {
|
|
process.stderr.write('gstack-question-log: tool_use_id must be string <=128 chars\n');
|
|
process.exit(1);
|
|
}
|
|
}
|
|
|
|
// Optional: free_text — sanitize (no newlines, <=300 chars).
|
|
if (j.free_text !== undefined) {
|
|
if (typeof j.free_text !== 'string') {
|
|
process.stderr.write('gstack-question-log: free_text must be string\n');
|
|
process.exit(1);
|
|
}
|
|
if (j.free_text.length > 300) j.free_text = j.free_text.slice(0, 300);
|
|
j.free_text = j.free_text.replace(/\n+/g, ' ');
|
|
}
|
|
|
|
// Required: question_summary (non-empty, <=200 chars, no newlines)
|
|
if (typeof j.question_summary !== 'string' || !j.question_summary.length) {
|
|
process.stderr.write('gstack-question-log: question_summary required\n');
|
|
process.exit(1);
|
|
}
|
|
if (j.question_summary.length > 200) {
|
|
j.question_summary = j.question_summary.slice(0, 200);
|
|
}
|
|
if (j.question_summary.includes('\n')) {
|
|
j.question_summary = j.question_summary.replace(/\n+/g, ' ');
|
|
}
|
|
|
|
// Injection defense on the summary — shared audited list (lib/jsonl-store.ts),
|
|
// same source of truth as learnings-log and decision-log. The previous local
|
|
// duplicate drifted (#1934): pattern fixes to the lib never propagated here.
|
|
if (hasInjection(j.question_summary)) {
|
|
process.stderr.write('gstack-question-log: question_summary contains suspicious instruction-like content, rejected\n');
|
|
process.exit(1);
|
|
}
|
|
|
|
// Registry lookup for category + door_type enrichment.
|
|
// Registry file is at \$GSTACK_ROOT/scripts/question-registry.ts, but we don't import
|
|
// TypeScript at runtime here — we pass through what was provided and fill in defaults.
|
|
// The caller (the preamble resolver) is expected to pass category+door_type from
|
|
// the registry when it knows them; for ad-hoc ids both can be omitted.
|
|
|
|
const ALLOWED_CATEGORIES = ['approval', 'clarification', 'routing', 'cherry-pick', 'feedback-loop'];
|
|
if (j.category !== undefined) {
|
|
if (!ALLOWED_CATEGORIES.includes(j.category)) {
|
|
process.stderr.write('gstack-question-log: invalid category, must be one of: ' + ALLOWED_CATEGORIES.join(', ') + '\n');
|
|
process.exit(1);
|
|
}
|
|
}
|
|
|
|
const ALLOWED_DOORS = ['one-way', 'two-way'];
|
|
if (j.door_type !== undefined) {
|
|
if (!ALLOWED_DOORS.includes(j.door_type)) {
|
|
process.stderr.write('gstack-question-log: invalid door_type, must be one-way or two-way\n');
|
|
process.exit(1);
|
|
}
|
|
}
|
|
|
|
// options_count — positive integer if present
|
|
if (j.options_count !== undefined) {
|
|
const n = Number(j.options_count);
|
|
if (!Number.isInteger(n) || n < 1 || n > 26) {
|
|
process.stderr.write('gstack-question-log: options_count must be integer in [1, 26]\n');
|
|
process.exit(1);
|
|
}
|
|
j.options_count = n;
|
|
}
|
|
|
|
// user_choice — required; <= 64 chars; single-line; no injection patterns
|
|
if (typeof j.user_choice !== 'string' || !j.user_choice.length) {
|
|
process.stderr.write('gstack-question-log: user_choice required\n');
|
|
process.exit(1);
|
|
}
|
|
if (j.user_choice.length > 64) j.user_choice = j.user_choice.slice(0, 64);
|
|
j.user_choice = j.user_choice.replace(/\n+/g, ' ');
|
|
|
|
// recommended — optional, same constraints as user_choice
|
|
if (j.recommended !== undefined) {
|
|
if (typeof j.recommended !== 'string') {
|
|
process.stderr.write('gstack-question-log: recommended must be string\n');
|
|
process.exit(1);
|
|
}
|
|
if (j.recommended.length > 64) j.recommended = j.recommended.slice(0, 64);
|
|
}
|
|
|
|
// followed_recommendation — compute if both sides present. An __unknown__
|
|
// choice means extraction failed, not that the user rejected the
|
|
// recommendation — leave the field absent so metrics can't be poisoned.
|
|
// Strip a trailing (Recommended) marker from BOTH sides before comparing:
|
|
// recommended usually arrives pre-stripped while user_choice is the raw
|
|
// option label, so a user who picked the recommended option was scored as
|
|
// NOT following it (#2400). NB: this JS lives inside a double-quoted
|
|
// bun -e string — never use double quotes in it.
|
|
if (j.recommended !== undefined && j.user_choice !== undefined && j.user_choice !== '__unknown__') {
|
|
const stripRec = (s) => String(s).replace(/\s*\(recommended\)\s*$/i, '').trim();
|
|
j.followed_recommendation = stripRec(j.user_choice) === stripRec(j.recommended);
|
|
}
|
|
|
|
// session_id — kebab-friendly; <=64 chars
|
|
if (j.session_id !== undefined) {
|
|
if (typeof j.session_id !== 'string') {
|
|
process.stderr.write('gstack-question-log: session_id must be string\n');
|
|
process.exit(1);
|
|
}
|
|
if (j.session_id.length > 64) j.session_id = j.session_id.slice(0, 64);
|
|
}
|
|
|
|
// Inject timestamp if not present.
|
|
if (!j.ts) j.ts = new Date().toISOString();
|
|
|
|
console.log(JSON.stringify(j));
|
|
" 2>"$TMPERR")
|
|
VALIDATE_RC=$?
|
|
set -e
|
|
|
|
if [ $VALIDATE_RC -ne 0 ] || [ -z "$VALIDATED" ]; then
|
|
if [ -s "$TMPERR" ]; then
|
|
cat "$TMPERR" >&2
|
|
fi
|
|
exit 1
|
|
fi
|
|
|
|
LOG_FILE="$GSTACK_HOME/projects/$SLUG/question-log.jsonl"
|
|
|
|
# Cathedral T5: composite-source dedup. If this exact (source, tool_use_id)
|
|
# was already logged within the last 100 lines, skip — protects against
|
|
# hook + agent both writing the same fire (D3 plan-tune cathedral decision).
|
|
# Lookup is bounded so the bin stays cheap on hot paths.
|
|
DEDUP_SKIP=""
|
|
if [ -f "$LOG_FILE" ]; then
|
|
DEDUP_SKIP=$(VALIDATED_JSON="$VALIDATED" LOG_FILE_PATH="$LOG_FILE" bun -e '
|
|
const fs = require("fs");
|
|
const j = JSON.parse(process.env.VALIDATED_JSON);
|
|
if (!j.tool_use_id) { console.log(""); process.exit(0); }
|
|
const want = j.source + ":" + j.tool_use_id;
|
|
const lines = fs.readFileSync(process.env.LOG_FILE_PATH, "utf-8").trim().split("\n").slice(-100);
|
|
for (const ln of lines) {
|
|
try {
|
|
const p = JSON.parse(ln);
|
|
if (p.source && p.tool_use_id && (p.source + ":" + p.tool_use_id) === want) {
|
|
console.log("dup");
|
|
process.exit(0);
|
|
}
|
|
} catch {}
|
|
}
|
|
console.log("");
|
|
' 2>/dev/null)
|
|
fi
|
|
|
|
if [ "$DEDUP_SKIP" = "dup" ]; then
|
|
echo "DEDUP: skipped (source=$(echo "$VALIDATED" | bun -e 'const j=JSON.parse(await Bun.stdin.text()); console.log(j.source);'), tool_use_id duplicate)"
|
|
exit 0
|
|
fi
|
|
|
|
echo "$VALIDATED" >> "$LOG_FILE"
|
|
|
|
# Cathedral T5: fire-and-forget --derive so inferred dimensions stay current
|
|
# without per-event latency (D17). Sub-second op; output suppressed; never
|
|
# blocks the hook caller. Skipped via GSTACK_QUESTION_LOG_NO_DERIVE=1 for
|
|
# tests that don't want the side effect.
|
|
if [ -z "${GSTACK_QUESTION_LOG_NO_DERIVE:-}" ]; then
|
|
(
|
|
nohup "$SCRIPT_DIR/gstack-developer-profile" --derive >/dev/null 2>&1 &
|
|
) >/dev/null 2>&1
|
|
fi
|
|
|
|
# NOTE: question-log.jsonl is deliberately NOT enqueued for gbrain-sync.
|
|
# Per Codex v2 review, audit/derivation data stays local alongside the
|
|
# question-preferences.json it annotates.
|